Breaking
November 22, 2024

iOS 18.1.1—Update Now Warning Issued To All iPhone Users Chris Mendez | usagoldmines.com

Update Nov. 21, 2024: This story, originally published Nov. 20, now includes details of a new CISA warning, as well as more expert advice on the fixes issued in iOS 18.1.1 and iOS 17.7.2.

Apple has issued iOS 18.1.1, an emergency iPhone update that you should apply now. That’s because iOS 18.1.1 fixes two serious security vulnerabilities, both of which are already being used in real-life attacks.

Apple doesn’t give much information about what’s fixed in iOS 18.1.1, to give people as much time to update as possible before more attackers get hold of the details. But the iPhone maker does say the iOS 18.1.1 update “provides important security fixes and is recommended for all users.”

Tracked as CVE-2024-44308, the first issue patched in iOS 18.1.1 is a flaw in the JavaScriptCore framework that could result in code execution if the user interacts with maliciously crafted web content. “Apple is aware of a report that this issue may have been actively exploited on Intel-based Mac systems,” the iPhone maker said on its support page.

The second issue patched in iOS 18.1.1, tracked as CVE-2024-44309, is a flaw in WebKit, the engine that underpins Apple’s Safari browser. If exploited, a user could fall victim to a cross-site scripting attack, which sees an attacker inject malicious code into a trusted website or application.

Again, Apple said it is aware of a report that this issue “may have been actively exploited on Intel-based Mac systems.”

Alongside iOS 18.1.1, Apple has also released iOS 17.7.2, for people with older devices or who do not want to upgrade to iOS 18 yet, fixing the same two vulnerabilities.

Apple has also released macOS Sequoia 15.1.1 and visionOS 2.1.1 to fix the already-exploited flaws.

New CISA Warning—Update To iOS 18.1.1 Or iOS 17.7.2

The US Cybersecurity and Infrastructure Agency (CISA) has also issued a warning, telling businesses and users to update to iOS 18.1.1 or iOS 17.7.2, macOS Sequoia 15.1.1, visionOS 2.2.2 and Safari 18.1.1 as soon as possible. “Apple released security updates to address vulnerabilities in multiple Apple products,” the CISA alert says.

CISA says the Apple updates are important because “a cyber threat actor could exploit some of these vulnerabilities to take control of an affected system.”

With this in mind, the agency says it encourages users and administrators to review the advisories and “apply necessary updates.”

Why You Should Update To iOS 18.1.1 Now

While there are only two vulnerabilities fixed in iOS 18.1.1, they are “significant,” says Sean Wright, head of application security at Featurespace. “The JavaScriptCore vulnerability could allow attackers to remotely target victims to execute code on their devices,” he says. “This code would hopefully be limited to existing sandbox protections, but it could allow attackers to do things such as redirect users to malicious sites and potentially steal session tokens.”

ForbesiOS 18.1—Apple Secretly Added A Cool New iPhone Security Feature

The other vulnerability in WebKit could have a similar impact to the JavaScriptCore vulnerability, says Wright. Due to the way Apple enforces browsers on its ecosystem, this will likely affect all browsers across the tech giant’s ecosystem including iPhones, iPads and Macs, he says.

Apple’s iOS 18.1.1 and iPadOS 18.1.1 include two important security fixes to bugs that could allow attackers to remotely compromise a user’s device, says Michael Covington, VP of Strategy at Jamf.

While Apple has warned that the vulnerabilities, also present in macOS, may be actively exploited on Intel-based systems, he recommends “updating any device that is at risk.”

CVE-2024-44308 allows attackers to compromise the device when malicious code is injected in the web content, says Covington.

CVE-2024-44309 , the flaw in WebKit, enables cross-site scripting attacks by exploiting how cookies are managed, Covington explains. “Vulnerabilities in WebKit are important to patch quickly as it is the framework that powers Safari, and also presents other web-based content to users.”

Given that the two vulnerabilities patched in iOS 18.1.1 are being used in attacks, Wright advises “updating as soon as you can.”

Also, be extra vigilant about the sites you browse and any links that you click on, he says.

The fixes provided by Apple introduce stronger checks to detect and prevent malicious activity, as well as improve how devices manage and track data during web browsing, Covington adds.

With attackers potentially exploiting both vulnerabilities, he says it is “critical that users and mobile-first organisations apply the latest patches as soon as they are able.”

Apple’s iOS 18.1.1 is available for the Phone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later and iPad mini 5th generation and later.

Make no mistake, the flaws patched in iOS 18.1.1 and iOS 17.7. 2 are serious, hence Apple’s need to issue this as an emergency, security-only iPhone update. You know what to do, go to your Settings > General > Software Update and download and install iOS 18.1.1 or 17.7.2 now.

 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

Apple Pay to Be Treated Like a Bank With Federal Scrutiny in the U.S. Chris Mendez | usagoldmines.co...
Apple Pay, Cash App, PayPal and other apps to be treated more like banks Chris Mendez | usagoldmines...
Gemini is making it easier to analyze files on your Android phone Chris Mendez | usagoldmines.com
Samsung Galaxy S23 FE gets security boost with November 2024 update Chris Mendez | usagoldmines.com
The Motorola Razr and Razr Plus 2024 plunge to record-low prices Chris Mendez | usagoldmines.com
Android 16 could go ‘even dimmer’ in a more convenient way for users Chris Mendez | usagoldmines.com
Apple still dominates US smartphone market Chris Mendez | usagoldmines.com
At its lowest price yet, the Motorola Razr+ (2024) is a true bargain this Black Friday Chris Mendez ...
Galaxy S23 November 2024 software update may finally go global Chris Mendez | usagoldmines.com
The US Consumer Financial Protection Bureau will now regulate Apple Pay, Venmo and others Chris Mend...
The US Consumer Financial Protection Bureau will now regulate Apple Pay, Venmo and others Chris Mend...
Google Wallet adds support for 18 new US banks in time for holiday deals Chris Mendez | usagoldmines...
European mobile payment system Wero launches in Belgian banks Chris Mendez | usagoldmines.com
Oppo smartphones are getting Google’s Circle to Search Chris Mendez | usagoldmines.com
Google Pay integrates Afterpay and Klarna BNPL services in US Chris Mendez | usagoldmines.com
New leak confirms early 2025 release for iPhone SE 4 — here’s what we know Chris Mendez | usagoldmin...
The Galaxy A56 may get one of the S24 Ultra’s top features Macky Briones | usagoldmines.com
Wi-Fi QR code sharing gets Material You change Chris Mendez | usagoldmines.com
ESR’s Geo MagSafe Wallet with built-in Apple Find My drops down to $29.50 today Chris Mendez | usago...
Undergrave, Super Onion Boy 2, Cubasis 3, more Chris Mendez | usagoldmines.com
Forget iPhone 16 Pro Max, the Asus ROG Phone 9 Pro has the best battery life we’ve ever seen Chris M...
These are the Android apps I ditched, and for good reason Chris Mendez | usagoldmines.com
Android 16 is now available for early testers Chris Mendez | usagoldmines.com
Android 16 notification cooldown is here to bring you peace Chris Mendez | usagoldmines.com
Android 16 notification cooldown is here to bring you peace Chris Mendez | usagoldmines.com
Apple confirms fix for disappearing Notes after iCloud terms issue Chris Mendez | usagoldmines.com
Nomad Black Friday Sale 2024: Deals on Chargers, iPhone Cases Chris Mendez | usagoldmines.com
Google is transforming Chrome OS into Android Chris Mendez | usagoldmines.com
Lil Big Invasion, Old Man’s Journey, Inventioneers, more Chris Mendez | usagoldmines.com
Google reveals 2024’s best apps and games on the Play Store Chris Mendez | usagoldmines.com
Honor 300 leaks in series of live images Chris Mendez | usagoldmines.com
One UI 7 testing is underway for Samsung Galaxy A53 Chris Mendez | usagoldmines.com
Breaking: Samsung Galaxy A56 to get huge charging speed upgrade Chris Mendez | usagoldmines.com
More Motorola phones are getting the Android 15 upgrade Chris Mendez | usagoldmines.com
Brave on iOS adds new “Shred” button to wipe site-specific data Chris Mendez | usagoldmines.com
One UI on Galaxy S25 could offer smoother gameplay with this game mode addition Chris Mendez | usago...
West Des Moines son and dad develop app to help struggling families Chris Mendez | usagoldmines.com
West Des Moines son and dad develop app to help struggling families Chris Mendez | usagoldmines.com
Xiaomi Starts HyperOS 2 Rollout: These Phones Are Getting The Android 15 Update Chris Mendez | usago...
Samsung May Not Increase Galaxy S25 Ultra Price Chris Mendez | usagoldmines.com
Apple Confirms iPhone Missing Notes Bug And Shows How To Fix It Chris Mendez | usagoldmines.com
How to Get Started on Bluesky — an App Some Users Are Leaving X for Chris Mendez | usagoldmines.com
Your phone can now remind you when you’ve used an app for too long Chris Mendez | usagoldmines.com
Mobile Crypto Apps Are Climbing the Charts as Bitcoin Blasts Off Chris Mendez | usagoldmines.com
iOS 18.1: How to Proofread, Rewrite and Edit With Apple Intelligence Chris Mendez | usagoldmines.com
I tested the Pixel 9 Pro’s temperature sensor vs a thermal camera to see which is best — here’s the ...
Best smartphone deal: Get a tiny NanoPhone on sale for $99.97 Chris Mendez | usagoldmines.com
The expected colors for all three Samsung Galaxy S25 phones just leaked again Chris Mendez | usagold...
How New PopSockets CEO Jiayu Lin Wants To Build A ‘Beloved Lifestyle Brand’ Chris Mendez | usagoldmi...
LG’s stretchable display can expand by 50% Chris Mendez | usagoldmines.com
Android seeks to solve the password problem once and for all Chris Mendez | usagoldmines.com
November 2024 EMUI update is live for Huawei P60 Pro, Mate X3, and Nova 9 Chris Mendez | usagoldmine...
MagicOS 9.0 (Android 15) third closed beta phase to begin later this month Chris Mendez | usagoldmin...
Verizon US Galaxy S21 series gets November 2024 security update Chris Mendez | usagoldmines.com
Apple @ Work: iOS 18.1 brings important features for device management Chris Mendez | usagoldmines.c...
Cash App Settlement: 1 Week Left to Claim Up to $2,500 Chris Mendez | usagoldmines.com
Cash App Settlement: 1 Week Left to Claim Up to $2,500 Chris Mendez | usagoldmines.com
Nothing OS 3.0 gets a second beta as Android 15’s stable release nears Chris Mendez | usagoldmines.c...
BlackBerry’s QNX operating system is now free for non-commercial use Chris Mendez | usagoldmines.com
Pay-as-You-Go Helps LatAm Consumers Battle ‘Prepaid Fatigue’ Chris Mendez | usagoldmines.com
7 Best Cheap Smartphones (2024): iPhone, Android, 5G Macky Briones | usagoldmines.com
Google will fix biggest complaints of Pixel owners with Tensor G6 Chris Mendez | usagoldmines.com
One UI 7 first beta tipped to soon hit Galaxy devices in South Korea and the US Chris Mendez | usago...
FCC visit for the Moto G Power 5G (2025) reveals battery capacity and charging speed Chris Mendez | ...
Motorola Edge 50 in for review Chris Mendez | usagoldmines.com
What Happens When Someone Accidentally Venmos You $300? Chris Mendez | usagoldmines.com
The ‘safe’ app for teens to talk mental health Chris Mendez | usagoldmines.com
OnePlus 12R now getting Android 15-based OxygenOS 15 update Chris Mendez | usagoldmines.com
My time using the Pixel 9 Pro’s underwater camera mode in Hawaii Chris Mendez | usagoldmines.com
Apple Quietly Introduced iPhone Reboot Code Which is Locking Out Cops Chris Mendez | usagoldmines.co...
Google all but admits Android TV is its neglected ‘other’ operating system in this week’s news Halli...
Samsung Tri-Fold phone won’t remain a dream Chris Mendez | usagoldmines.com
Huawei Mate 70 series could begin official sale in early December Chris Mendez | usagoldmines.com
Huge early Black Friday phone sale drops the Motorola Edge 2024 down to just $350 Chris Mendez | usa...
Samsung November 2024 One UI Updates Chris Mendez | usagoldmines.com
Older Samsung phones won’t be able to run this app: act before December 23 Chris Mendez | usagoldmin...
Samsung Early Black Friday Sale – Save On Smartphones, Gaming Monitors, Smart Watches, And More Chri...
This fantastic $399 Motorola comes with a built-in stylus and a free pair of Bose earbuds Macky Brio...
I have a frozen Motorola Edge phone – is this a lost cause? Chris Mendez | usagoldmines.com
Brits in China shocked by tech that allows you to pay with your hand Chris Mendez | usagoldmines.com
MEGA MAN X, Ace Attorney Trilogy, and more Chris Mendez | usagoldmines.com
Why Does Target App Say Product in Stock When It’s Not on Shelf? Chris Mendez | usagoldmines.com
Google admits Tensor overheating is the #1 reason for Pixel returns Chris Mendez | usagoldmines.com
Period Tracking App Refuses To Disclose Data to American Authorities Chris Mendez | usagoldmines.com
All Cell Phones In Michigan Going Through Massive Change Chris Mendez | usagoldmines.com
Unofficial Galaxy S25 Ultra render shows Samsung’s bold new color picks Chris Mendez | usagoldmines....
Patent shows more details of Samsung’s potential tri-fold phone Chris Mendez | usagoldmines.com
Pixel users expect 36 hours of battery in planning Tensor G6 Chris Mendez | usagoldmines.com
Last Week to Apply – Cash App to make Direct Payment of $2570 to More than 7 million People for data...
Google Pixel Phones Are Finally Getting a Built-In Battery Saving Tool Chris Mendez | usagoldmines.c...
The OnePlus Open renewed my faith in folding phones. Here’s why Macky Briones | usagoldmines.com
New ‘crazy’ iPhone feature means you can take control of other people’s screens and use their phones...
Galaxy S25 Slim won’t launch alongside other S25 phones: Tipster Chris Mendez | usagoldmines.com
Have you been seeing more Pixel phones in the wild? [Poll] Chris Mendez | usagoldmines.com
Woot Deals of the Day: This Pixel Phone Is 64% Off Right Now (Down To $400) Chris Mendez | usagoldmi...
Nokia 9210 Communicator Used a Fluorescent Tube for Display Backlight Chris Mendez | usagoldmines.co...
Google Pixel Phones Are Finally Getting a Built-In Battery Saving Tool Chris Mendez | usagoldmines.c...
I used the Google Pixel 9 Pro XL and Apple iPhone 16 Pro Max for a week: Here’s what I learned Chris...
We Have ADHD. These Are The Apps We Swear By. Chris Mendez | usagoldmines.com
MagicOS 9.0 first beta rollout begins with new camera features Chris Mendez | usagoldmines.com

Leave a Reply